From b3e0802a629b2fc41184e7f15e355b20d145e099 Mon Sep 17 00:00:00 2001 From: jsing Date: Tue, 29 Jun 2021 19:33:46 +0000 Subject: [PATCH] Simplify RSA PSS key size comment. Wording provided by tb@ --- lib/libssl/ssl_sigalgs.c | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/lib/libssl/ssl_sigalgs.c b/lib/libssl/ssl_sigalgs.c index b503503105f..619ba57f0de 100644 --- a/lib/libssl/ssl_sigalgs.c +++ b/lib/libssl/ssl_sigalgs.c @@ -1,4 +1,4 @@ -/* $OpenBSD: ssl_sigalgs.c,v 1.35 2021/06/29 19:29:16 jsing Exp $ */ +/* $OpenBSD: ssl_sigalgs.c,v 1.36 2021/06/29 19:33:46 jsing Exp $ */ /* * Copyright (c) 2018-2020 Bob Beck * Copyright (c) 2021 Joel Sing @@ -270,10 +270,7 @@ ssl_sigalg_pkey_ok(SSL *s, const struct ssl_sigalg *sigalg, EVP_PKEY *pkey) if (sigalg->key_type != pkey->type) return 0; - /* - * RSA PSS must have an RSA key that needs to be at - * least as big as twice the size of the hash + 2 - */ + /* RSA PSS must have a sufficiently large RSA key. */ if ((sigalg->flags & SIGALG_FLAG_RSA_PSS)) { if (pkey->type != EVP_PKEY_RSA || EVP_PKEY_size(pkey) < (2 * EVP_MD_size(sigalg->md()) + 2)) -- 2.20.1